RE: sbs2003 pdc and bdc no DNS name listed.

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hi Brian,

Thank you for your prompt response.

From your active directory export file you mail to me, I don't find any
duplicate object name with CLISBS.CLILANG.LOCAL Windows SBS server. So I
believe duplicate server node shouldn't cause the Kerberos error, there
should be other reason to the problem.

Please refer to the following steps to narrow down this issue:

1. The SRV records are necessary for domain controller to be located,
please recreate it and let me know whether the issue disappears:

1) Run "net stop netlogon"
2) Run "ipconfig /flushdns"
4) Rename netlogon.dnb and netlogon.dns to oldnetlogon.dnb and
oldnetlogon.dns in the folder %systemroot%\system32\config\
5) Run "net start netlogon"
6) Run "ipconfig /registerdns"

2. Please send me the DNS database for further investigation. The
domain.com.dns file and domain.com.dns.log files are located at
%systemroot%\system32\dns.

If the zone is Active Directory integrated zone so the DNS records are
stored in AD instead of the folder on the server. In that case, we can use
dnscmd utility to export the zone file. Please refer to the following KB
for instruction:

304489 Extracting DNS Active Directory-Integrated Zone Files
http://support.microsoft.com/?id=304489

In additional, I find a similar problem about Kerberos Event ID 4, and this
issue may caused by same SPN in DNS. A service principal name (SPN) is the
name by which a client uniquely identifies an instance of a service. If you
install multiple instances of a service on computers throughout a forest,
each instance must have its own SPN. A given service instance can have
multiple SPNs if there are multiple names that clients might use for
authentication. For more information on SPN:

http://msdn.microsoft.com/library/default.asp?url=/library/en-us/ad/ad/servi
ce_principal_names.asp

http://www.microsoft.com/resources/documentation/Windows/2000/server/reskit/
en-us/Default.asp?url=/resources/documentation/Windows/2000/server/reskit/en
-us/distrib/dsbd_int_brkw.asp

Please let me know the result above and thanks for your time and patience.

Have a great day.

Best Regards,

Steven Zhu
MCSE
Microsoft Online Partner Support
Get Secure! - www.microsoft.com/security
======================================================
PLEASE NOTE the newsgroup SECURE CODE and PASSWORD were
updated on February 14, 2006.? Please complete a re-registration process
by entering the secure code mmpng06 when prompted. Once you have
entered the secure code mmpng06, you will be able to update your profile
and access the partner newsgroups.
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
======================================================







.



Relevant Pages

  • Re: 2008 DC Stops responding to local logins
    ... Have a look on this articles, seems that the promotion does not work correct, which causes the replication problem. ... Then restart the server. ... Verifying that the local machine dcontroller05, ... SPN found:LDAP/dcontroller05.campus.university.edu ...
    (microsoft.public.windows.server.active_directory)
  • Re: Kerberos Authentication to VWMare...
    ... A Kerberos Error Message was received: ... Server Realm: ... We have checked the SPN using SetSPN with -L option and see that both MOSS ...
    (microsoft.public.windows.server.security)
  • Re: Domain Replication Problems
    ... the NTFRS is responsible for file replicating the actual GPT ... Mail server crash, I was able to recover it and I setup a software RAID ... is the Schema Owner, but is deleted. ... Failed can not test for HOST SPN ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain Replication Problems
    ... Mail server crash, I was able to recover it and I setup a software RAID ... The DC MAIL is advertising itself as a DC and having a DS. ... is the Schema Owner, but is deleted. ... Failed can not test for HOST SPN ...
    (microsoft.public.windows.server.active_directory)
  • Re: Kerberos NTLM
    ... I'll assume it was just a typo, and you do have an SPN registered for your IIS computer account as HTTP/server1.domain.com. ... you want to follow some basic Kerberos troubleshooting steps (like making sure the time is correct on both client and server). ... Joseph T. Corey MCSE, Security+ ...
    (microsoft.public.windows.server.active_directory)